Back Heise.De Cisco: Code injection vulnerability in Unity Connection and other flaws
Network equipment provider Cisco has released eight security advisories, some addressing highly risky vulnerabilities in several products. The most serious appear to be security flaws in Cisco's Unity Connection, which allow for the injection and execution of malicious code.
Two vulnerabilities are found in Cisco's Unity Connection. The more severe one allows authenticated attackers from the network to inject and execute malicious code via manipulated API requests to the web-based management interface. The second flaw, however, affects the web user interface of the Unity Connection Web Inbox and allows unauthenticated actors from the network to perform a Server-Side Request Forgery (SSRF) attack.
The Managed Switches of the SG350 and SG350X series have a Denial-of-Service vulnerability that logged-in attackers can trigger with prepared SNMP requests. Unauthenticated malicious actors from the network can disable Cisco's Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) by sending many connection requests due to an improper implementation of a rate-limiting mechanism for network connections. Multiple flaws in Cisco's IoT Field Network Director also allow logged-in attackers from the network to execute commands, access files, and perform Denial-of-Service attacks on managed routers.
The security vulnerabilities in detail, sorted by severity:
Most recently, Cisco closed several security vulnerabilities in various products in mid-April. The developers closed ten security flaws there, for example in Cisco's Identity Services Engine and Webex.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
